When you say 192.168.0.0 subnet, do you mean 192.168.0.0/24 subnet? And what do you mean by "to both sites"?
–
David SchwartzJan 2 '13 at 22:46

Is the endpoint of the VPN at HQ on the 192.168.200.0 subnet? If so, has the 192.168.0.0 subnet been configured with a route back to the 192.168.6.0 subnet? Is there a conflict with another subnet, possibly at the end of another site-to-site VPN? Consider the networks of any business partners.
–
Jonathan JJan 2 '13 at 23:00

Thanks for the comment. HQ has a couple of subnets: 200.x, 0.x, and 1.x. Where can I identify if it is routed back to BX site (6.x) subnet?
–
user151692Jan 3 '13 at 17:03

David, Yes that's what I meant. To both sites means that from Point A to B and Point B to A I am getting all the green checks with package track.
–
user151692Jan 3 '13 at 18:14

We called Cisco, and they confirmed that this was a bug of the ASA we use. The data was not being encrypted so ASA was not sending it back. Guess what? Tech told us to restart the firewall, and problem went away. It sounds stupid, but sometimes you have to remember: Router is a fing router and it requires fing restart. Excuse my language but I really got frustrated.
–
user151692Jan 10 '13 at 21:08